ZeroFox Cyber Intelligence Daily Brief - January 18, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 18, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- FTC Takes Action Against GM for Sharing Drivers’ Precise Location and Driving Behavior Data Without Consent
- Russia-Linked UAC-0063 Phishes Kazakh Government in Cyberespionage Campaign
- Austrian Non-Profit Sues Chinese Companies for Violating EU Data Protection Law
FTC Takes Action Against GM for Sharing Drivers’ Precise Location and Driving Behavior Data Without Consent
What happened: The Federal Trade Commission (FTC) is taking action against General Motors (GM) and OnStar over allegations they collected, used, and sold drivers’ precise geolocation data and driving behavior information from millions of vehicles—data that can be used to set insurance rates—without adequately notifying consumers and obtaining their affirmative consent.
Why it matters: In its complaint, the FTC alleged that Michigan-based GM used a misleading enrollment process to get consumers to sign up for its OnStar connected vehicle service and the OnStar Smart Driver feature. GM failed to clearly disclose that it collected consumers’ precise geolocation and driving behavior data and sold it to third parties, including consumer reporting agencies, without consumers’ consent. Under a proposed order settling the FTC’s allegations, General Motors LLC, General Motors Holdings LLC, and OnStar LLC (owned by General Motors Company), will be banned for five years from disclosing consumers’ sensitive geolocation and driver behavior data to consumer reporting agencies.
Russia-Linked UAC-0063 Phishes Kazakh Government in Cyberespionage Campaign
What happened: Russia-linked group UAC-0063 is targeting Kazakhstan in a cyberespionage campaign, using spear-phishing lures tied to legitimate Kazakh government documents. These attacks aim to collect intelligence from government, NGO, and defense sectors across Central Asia and Eastern Europe.
Why it matters: Kazakhstan was observed to be one of Russia’s allies but as the war between Russia and Ukraine began, Kazakhstan likely began shifting its stance away as seen in new trade agreements with both Western states and China. In this cyberespionage campaign, Russia’s interest in Kazakhstan likely indicates that Russia is monitoring its allies, since researchers have uncovered documents stolen in the campaign involving letters from Kazakhstan's embassies, its president’s visits to other regions, and more.
Austrian Non-Profit Sues Chinese Companies for Violating EU Data Protection Law
Source: https://thehackernews.com/2025/01/european-privacy-group-sues-tiktok-and.html
What happened: Austrian non-profit None of Your Business (noyb) is suing several China-based companies—including TikTok, AliExpress, Temu, WeChat, and Xiaomi—for violating the European Union’s data protection regulations. Nyob has accused these companies of transferring Europeans’ personal data to China.
Why it matters: Violating data protection regulations, which are in place to protect user data, is a likely indication of deliberate attempts to access and exfiltrate sensitive data for an adversarial state to give it a strategic upper hand. Adversarial states are often likely to use such data to influence public opinions, spread incendiary disinformation, and disrupt key processes like elections. Moreover, these accusations come as TikTok heads towards a shutdown in the United States, with allegations of the social media platform being spyware.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user empathy: On January 17, 2025, threat actor "empathy" claimed to have leaked a database associated with Emirates Cancer Society, a UAE-based organization that provides support and assistance to cancer patients and their families, on BreachForums.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-12805: A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution. Affected products: The affected products and platforms are listed in this advisory.
Tags: DIB, tlp:green